To help break through CVE noise and focus on high-impact, exploitable issues, a growing number of security teams have started to consider additional inputs for prioritizing vulnerabilities. Among them is EPSS (the Exploit Prediction Scoring System), which measures how likely a particular vulnerability is to be exploited in the wild.
EPSS scores can be used alongside CVSS scores, reachability analysis, and VEX information to facilitate effective vulnerability prioritization.
We’d invite you to join Jay Jacobs — EPSS co-chair and creator — in our upcoming webinar to learn best practices for using EPSS in your organization's vulnerability management program. Topics will include:
-Details of the EPSS data model
-Benefits of using EPSS
-How EPSS differs from other vulnerability scoring systems like CVSS, SSVC, and the new VISS (Vulnerability Impact Scoring System)
-Strategies for using EPSS scores alongside other inputs to effectively prioritize vulnerabilities